Solutions  ·  2026-07-30

Model Context Protocol 2026-07-28 spec finalized — stateless core, OAuth/OIDC-aligned authorization

SolutionsHigh impactGlobal
The Agentic AI Foundation finalized (July 28, 2026) the largest MCP specification revision since launch: a stateless protocol core removing session state/handshake, plus hardened authorization aligned with OAuth 2.0/OpenID Connect and a formal deprecation policy; SDKs (including Microsoft's C# SDK v2.0) shipped support day-of.
MCP underpins nearly all enterprise agent-to-tool integrations (approaching 1B+ SDK downloads); the security-hardening changes directly affect the attack surface behind dozens of MCP CVEs disclosed in the same window (SSRF, path traversal, broken auth), making this the most consequential AI-agent infrastructure security change of the period.
Every organization running MCP servers/clients must test against the new spec immediately — legacy stateful implementations are not automatically compatible and some session-based security assumptions break.
Model Context Protocol blogThe RegisterModel Context Protocol Blog — 2026-07-28 Release Candidate (background)AWS Machine Learning Blog — How AgentCore Gateway supports the MCP 2026-07-28 specGitHub Changelog — GitHub MCP Server supports the next MCP specification
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →